Sceawere

Vulnerability Detail

CVE-2026-88252UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SSSD Responder File Descriptor Exhaustion

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
7h ago
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
Attack Type
Loop with Unreachable Exit Condition ('Infinite Loop')
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
HIGH

Narrative and Response

Description

A flaw was found in sssd. A local user can cause a Denial of Service (DoS) by exhausting the responder service's available file descriptors (system handles used for open connections). By opening and maintaining many concurrent connections to a responder socket while continuing to queue new connection attempts, an attacker can trigger an unthrottled retry loop. This condition leads to high CPU utilization and stalls the service, preventing legitimate identity and authentication requests from being processed.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-10-06T18:16:56.867Z",
  "pubdate": "2026-10-06T18:16:56.867Z",
  "executiveSummary": "A vulnerability in sssd allows local authenticated users to perform a Denial of Service (DoS) attack by exhausting available file descriptors.\nThe flaw resides within the responder service, which manages concurrent identity and authentication connection requests.\nBy intentionally opening and maintaining a high volume of concurrent connections to the responder socket, an attacker can induce an unthrottled retry loop.\nThis behavior leads to resource contention characterized by excessive CPU utilization and service stalling, effectively blocking legitimate authentication and identity lookups.\nThe vulnerability is exploitable locally and does not require elevated privileges, posing a risk to system stability in environments relying on sssd for centralized authentication.\nSuccessful exploitation prevents the system from processing essential requests, resulting in a complete denial of service for sssd-dependent operations.",
  "technicalDetails": "The vulnerability originates from inadequate connection management and resource throttling mechanisms within the sssd responder component. The responder service is responsible for handling IPC-based requests for identity information and authentication.\nThe flaw is triggered when an attacker initiates multiple concurrent connections to the responder socket. By maintaining these connections and continuously queuing new requests, the attacker induces a condition where the service fails to manage the influx of file descriptors efficiently.\nUpon reaching the file descriptor limit, the internal logic of the responder service enters an unthrottled retry loop. This loop attempts to recover or manage the connection overhead without appropriate backoff or request-limiting logic, resulting in a CPU-intensive busy-wait state or thrashing condition.\nAttack Flow: 1. The local user initiates a series of socket connections to the sssd responder endpoint. 2. The user maintains these connections, consuming system-level file handles. 3. The user continues to queue additional connection attempts, forcing the responder to allocate further resources until the process limit is reached. 4. The service encounters an error state due to descriptor exhaustion and enters an unthrottled retry loop. 5. High CPU cycles are consumed attempting to process the backlog, stalling the event loop and effectively preventing the service from responding to legitimate authentication requests.\nBecause the vulnerability impacts the responder service process, it affects the ability of the system to resolve users or perform authentication tasks, essentially rendering local and network-based identity lookups unavailable until the process is restarted or the load is removed.\nThe primary risk factor is the lack of rate-limiting or concurrency control on incoming socket connections, which allows a single local process to monopolize the responder's event-handling capabilities."
}
CVE-2026-88252: SSSD Responder File Descriptor Exhaustion (MEDIUM Severity, CVSS: 4.7) | Sceawere